Antibot - #267
Draft
ossftw wants to merge 7 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Earlier today I was given access to
Antibot.tsfrom https://multiplayerpiano.net. So, I rewrote it for compatibility within NodeWorldOfText. To circumvent the issue of AI-indexing and overall reverse-engineering, I came up with the idea to put theclient_checksandbot_globalsinnwotdata/settings.json. As you may notice, these arrays are not insettings_example.json. This is intentional. I have made it so that if theantibotobject is not written intonwotdata/settings.json, the antibot is disabled. This also gives fork maintainers more freedom per instance.How it works (as of now): when a client connects, the server sends an obfuscated JavaScript challenge (todo: change module) (
antibot_challenge) containing 3 randomly-selected browser environment checks (fromclient_checks) and all automation-tool detection checks (frombot_globals). The client must eval the code in a browser context (bot globals cause it to return 0, fail) while passing client checks contributes to a hash that gets sent back as anantibot_response. The server verifies the hash matches. if it does, the connection is marked verified and all subsequent msgs pass through, otherwise every msg is dropped.Todo: